PT-2021-4529 · Pillow+9 · Pillow+9

Published

2021-02-28

·

Updated

2026-03-31

·

CVE-2021-25290

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 8.1.1
Description An issue was discovered in the TiffDecode.c component of the Pillow image processing library, related to a lack of memory volume check for reading, which can lead to a denial of service. The issue involves a negative-offset memcpy with an invalid size. This can be exploited by a remote attacker.
Recommendations For versions prior to 8.1.1, update to version 8.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TiffDecode.c component until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4149
ALT-PU-2021-1491
BDU:2021-05182
BIT-PILLOW-2021-25290
CESA-2021_4149
CVE-2021-25290
DLA-2716-1
GHSA-8XJQ-8FCG-G5HW
OPENSUSE-SU-2021:1134-1
OPENSUSE-SU-2021_1134-1
OPENSUSE-SU-2024:11209-1
OPENSUSE-SU-2024:13827-1
OPENSUSE-SU-2024_1673-1
PYSEC-2021-36
RHSA-2021:4149
RHSA-2021_4149
RLSA-2021:4149
SUSE-SU-2021:1938-1
SUSE-SU-2021:1939-1
SUSE-SU-2021:1940-1
SUSE-SU-2024:1673-1
SUSE-SU-2024:1673-2
USN-4763-1
USN-8135-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Pillow
Red Hat
Rocky Linux
Suse
Ubuntu